The PCI DSS requires that different types of scans be performed, and at different intervals. We are often asked what the difference is between external ASV scans, internal vulnerability scans, penetration tests, segmentation tests, and application code scans. It is important to understand the differences between these scan types and the corresponding requirements of each:
Quarterly External Vulnerability Scans (Requirement 11.3.2) - ASV scans, at least once every three months by an ASV. All vulnerability scans performed by ServerScan are ASV-certified and satisfy this PCI DSS requirement.
Quarterly Internal Vulnerability Scans (Requirement 11.3.1) – At least once every three months from inside your network. PCI DSS 4.0.1 now requires that these be "authenticated" scans (Requirement 11.3.1.2).
Annual Penetration Testing (Requirement 11.4.1-11.4.3) - At least once a year by a qualified penetration tester. Penetration tests performed by ServerScan can be used to satisfy this requirement.
Segmentation Testing (Requirement 11.4.5 and 11.4.6) – Annually for merchants, every six months for service providers. Segmentation penetration tests performed by ServerScan satisfy this requirement.
Payment Page Integrity Monitoring (Requirement 11.6.1) - Payment pages must be monitored for unauthorized changes to security-impacting HTTP headers and script contents, as received by the consumer's browser. This has been mandatory since 31 March 2025, alongside Requirement 6.4.3, which asks you to list every script on the page and write down why each one is there. ServerScan payment page monitoring checks your payment pages every day and keeps that record for you, and what requirement 11.6.1 asks for covers the detail.
Still working out what your own scanning requirements are? Our PCI compliance guides cover how to scope a scan, which SAQ form applies to you, and what to do about a scan that fails. When you are ready to start, see what it costs. US-based email support is included with every plan, from the day you sign up.